[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-10-23 Thread Julian Andres Klode
** Description changed: - (This is uploaded to noble as 2.8.1 per - https://wiki.ubuntu.com/AptUpdates) + (Please see https://wiki.ubuntu.com/AptUpdates for the versioning) [Impact] - We have received feedback from users that use NIST-P256 keys for their repositories that are upset about rec

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-19 Thread Julian Andres Klode
** Changed in: apt (Ubuntu Noble) Milestone: ubuntu-24.04.1 => None -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073126 Title: More nuanced public key algorithm revocation To manage notificat

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-15 Thread Julian Andres Klode
** Description changed: (This is uploaded to noble as 2.8.1 per https://wiki.ubuntu.com/AptUpdates) [Impact] We have received feedback from users that use NIST-P256 keys for their repositories that are upset about receiving a warning. APT 2.8.0 in noble-proposed would bump the warning

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-06 Thread Launchpad Bug Tracker
This bug was fixed in the package apt - 2.9.7 --- apt (2.9.7) unstable; urgency=medium [ sid ] * Show installed version (not candidate version) while removing a package [ David Kalnischkies ] * Parse snapshot option for apt show/list (Closes: #1075819) [ Frans Spiesschaert

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-06 Thread Timo Aaltonen
** Tags removed: block-proposed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073126 Title: More nuanced public key algorithm revocation To manage notifications about this bug go to: https://bugs.

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-02 Thread Andreas Hasenack
** Tags added: block-proposed-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073126 Title: More nuanced public key algorithm revocation To manage notifications about this bug go to: https://b

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-02 Thread Timo Aaltonen
this upload is not to be accepted to -updates before the discussion on ubuntu-release@ is concluded ** Tags added: block-proposed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073126 Title: More n

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-02 Thread Timo Aaltonen
Hello Julian, or anyone else affected, Accepted apt into noble-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/apt/2.8.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://wiki.ubuntu.com/Tes

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-08-02 Thread Julian Andres Klode
** Description changed: + (This is uploaded to noble as 2.8.1 per + https://wiki.ubuntu.com/AptUpdates) + [Impact] We have received feedback from users that use NIST-P256 keys for their repositories that are upset about receiving a warning. APT 2.8.0 in noble-proposed would bump the warning

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-07-30 Thread Julian Andres Klode
** Description changed: [Impact] We have received feedback from users that use NIST-P256 keys for their repositories that are upset about receiving a warning. APT 2.8.0 in noble-proposed would bump the warning to an error, breaking them. We also revoked additional ECC curves, which may

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-07-30 Thread Julian Andres Klode
** Changed in: apt (Ubuntu Oracular) Status: New => Fix Committed ** Tags added: regression-proposed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073126 Title: More nuanced public key algo

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-07-15 Thread Julian Andres Klode
** Description changed: [Impact] We have received feedback from users that use NIST-P256 keys for their repositories that are upset about receiving a warning. APT 2.8.0 in noble-proposed would bump the warning to an error, breaking them. We also revoked additional ECC curves, which may

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-07-15 Thread Julian Andres Klode
** Description changed: [Impact] We have received feedback from users that use NIST-P256 keys for their repositories that are upset about receiving a warning. APT 2.8.0 in noble-proposed would bump the warning to an error, breaking them. + + We also revoked additional ECC curves, which may

[Bug 2073126] Re: More nuanced public key algorithm revocation

2024-07-15 Thread Julian Andres Klode
** Description changed: - APT 2.9.x and 2.8.0 revoke any of the non-asserted algorithms, we should - modify the mechanism such that only RSA1024 is raised to an error to - avoid unwanted regressions while still keeping the set of fully - supported algorithms small. + [Impact] + We have received fe